A reported operational security failure by the INC ransomware group enabled incident responders to identify attacker infrastructure and recover data stolen from 12 U.S. organizations. A forensic review of artifacts from an intrusion—initially detected when ransomware encryption activity hit a production SQL Server—revealed infrastructure that stored exfiltrated victim data beyond the single investigated case, allowing broader recovery efforts.
Cyber Centaurs (DFIR) traced the intrusion to a RainINC ransomware variant staged and executed from the Windows PerfLogs directory, a location increasingly abused by threat actors for staging. Investigators found renamed binaries (e.g., winupdate.exe) and PowerShell tooling, including a script (new.ps1) containing Base64-encoded Restic commands and hardcoded environment variables (e.g., access keys, repository paths, and S3 passwords) tied to encrypted repositories; although Restic was not used in the specific attack, these remnants shifted the work from incident response to infrastructure analysis and ultimately exposed reusable attacker storage repositories linked to multiple victims.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Cyber Centaurs published a detailed write-up describing the INC ransomware infrastructure mistake, the recovery process, and additional tooling used by the group. The report also included YARA and Sigma rules to help defenders detect Restic or renamed binaries used in ransomware staging.
After confirming the repositories' contents, Cyber Centaurs decrypted and preserved the backups and worked with law enforcement to validate ownership and handle the recovered data appropriately. This turned the attackers' operational security lapse into a multi-victim data recovery effort.
Using a custom non-destructive enumeration process, Cyber Centaurs identified attacker-controlled repositories containing encrypted exfiltrated data from 12 unrelated U.S. organizations across multiple sectors. The team accessed the storage using the attackers' own configuration and tooling approach without exploiting vulnerabilities or modifying the repositories.
During forensic analysis, researchers found leftover Restic-related artifacts, including PowerShell scripts and hardcoded repository credentials, even though Restic was not used in the specific intrusion. These artifacts allowed them to pivot from incident response into mapping infrastructure used by the INC ransomware operation.
Cyber Centaurs began investigating after a U.S. client discovered a RainINC ransomware variant encrypting a production SQL Server. The payload was traced to execution from the Windows PerfLogs directory.
Cyber Centaurs disclosed in November that it had successfully recovered data stolen by the INC ransomware gang due to the group's operational security failure. Full technical details were shared later in a public report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
cio.com
Open sourcescworld.com
Open sourcedatabreaches.net
Open sourcebleepingcomputer.com
Open sourcecybercentaurs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.